40%
Total Score
25
100
70
67
The package has had no release in more than five years, despite 11 releases overall; this strongly raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and limited ongoing maintenance.
A post-install-cmd script runs during installation, adding execution complexity and some supply-chain exposure; no other provided signal shows that this is safely constrained.
Only one registry maintainer is listed, leaving little visible publishing redundancy; the repository is user-owned, so no organizational backing compensates for that thin base.
The repository is not archived, which is a modest positive, but its last push was in January 2021 and does not offset the lack of recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version * | — | — |
topthink/think-view Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.